This detection identifies the presence of the ACProtect UltraPack 10x20xRiSco executable, which is frequently employed by malware authors to obfuscate malicious payloads and evade signature-based analysis. Proactive hunting for this specific packer in Azure Sentinel allows the SOC team to uncover hidden threats that may bypass standard antivirus solutions, ensuring early identification of potential fileless or packed attacks within the environment.
rule ACProtectUltraProtect10X20XRiSco
{
meta:
author="malware-lu"
strings:
$a0 = { 00 00 00 00 00 00 00 00 [12] 00 00 00 00 00 00 00 00 [13] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4B 45 52 4E 45 4C 33 32 2E 44 4C 4C 00 [16] 00 00 00 00 55 53 45 52 33 32 2E 44 4C 4C 00 [4] 00 00 00 00 [20] 00 00 00 00 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 00 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 00 45 78 69 74 50 72 6F 63 65 73 73 00 00 00 4D 65 73 73 61 67 65 42 6F 78 41 00 90 4D 69 6E 65 49 6D 70 6F 72 74 5F 45 6E 64 73 73 00 }
condition:
$a0
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the ACProtectUltraProtect10X20XRiSco detection rule, including suggested filters and exclusions:
Scenario: Deployment of New ACProtect-Patched Applications via SCCM
Image.Path contains \SCCM\ or \SoftwareDistribution\ AND Publisher matches “ACProtect Software” or specific trusted internal publishers (e.g., “Contoso Corp”).Scenario: Scheduled Antivirus Definition Updates on Endpoint Servers
UpdateService.exe or DefenderSvc.exe) with its own protection layer. When these services restart or execute their update logic, the YARA rule detects the packed binary structure as a potential “suspicious obfuscation” event.UpdateService.exe, DefenderSvc.exe) running under the context of the System account (NT AUTHORITY\SYSTEM). Additionally, exclude events occurring within a specific time window (e.g., 02:00–04:00 local time) when maintenance windows are active.Scenario: Execution of Internal DevOps Build Artifacts